Private
Public Access
The Tier 2 agent wrote audit_exception_handling.py output to C:\\Users\\Ed\\AppData\\Local\\Temp\\audit_initial.json via shell redirection. This is OUTSIDE the sandbox allowlist (which is C:\\projects\\manual_slop_tier2 + C:\\Users\\Ed\\AppData\\Local\\ manual_slop\\tier2 + C:\\Users\\Ed\\AppData\\Local\\manual_slop\\ tier2_failures). The OpenCode session-level guard fires the 'ask' prompt for paths outside the project root, which has no answer in an autonomous session, so ops halted mid-track. Fix (3 layers): 1. opencode.json.fragment: add bash deny rule '*AppData\\Local\\Temp\\*': 'deny' to BOTH the top-level permission.bash (for default agents) and the tier2-autonomous agent's permission.bash. The agent physically cannot run shell commands that target the global Temp dir. 2. conductor/tier2/agents/tier2-autonomous.md: add 'Temp files' convention telling the agent to use C:\\Users\\Ed\\AppData\\Local\\manual_slop\\tier2\\ for scratch / audit-output / intermediate files, NOT %TEMP%. 3. conductor/tier2/commands/tier-2-auto-execute.md: same convention in the slash command so the agent sees it at slash-command time. Tests (default-on): - test_agent_denies_temp_writes: agent prompt has the Temp deny in frontmatter bash + the app-data dir note - test_config_fragment_denies_temp_writes: both top-level and agent bash have the deny rule All 16 tier 2 slash command tests pass. Also: cleaned up the leaked audit_initial.json + audit.json + audit_after*.json from %TEMP% (they were leftovers from a prior run). Re-ran setup against the live clone; opencode.json's agent bash and top-level bash both have the deny rule.
56 lines
3.8 KiB
Markdown
56 lines
3.8 KiB
Markdown
---
|
|
description: Autonomously execute a conductor track in the Tier 2 sandbox
|
|
agent: tier2-autonomous
|
|
---
|
|
|
|
# /tier-2-auto-execute
|
|
|
|
Run a track autonomously in the Tier 2 sandboxed mode. No `permission: ask` prompts.
|
|
|
|
## Arguments
|
|
|
|
$ARGUMENTS - Track name (required). Examples: `result_migration_review_pass`, `data_structure_strengthening_20260606`.
|
|
Optional flags: `--resume` (continue from last completed task), `--toast` (Windows toast on give-up).
|
|
|
|
## Pre-flight
|
|
|
|
1. **Verify sandbox is active.** This slash command must be invoked from a sandboxed OpenCode session. If `manual-slop_get_ui_performance` returns an error or the run_tier2_sandboxed.ps1 wrapper is not in the parent process, refuse to start.
|
|
2. **Load the track spec.** Read `conductor/tracks/<track-name>/spec.md` and `plan.md` from the current branch. If the track does not exist, abort.
|
|
3. **Check for a previous run.** If `<app-data>/tier2/<track-name>/state.json` exists AND `--resume` is NOT set, abort with: "Previous run found for this track. Use `--resume` to continue, or delete the state file to start fresh."
|
|
|
|
## Protocol
|
|
|
|
1. `git fetch origin master` (NOTE: this repo uses `master`, not `main`; added 2026-06-17)
|
|
2. `git switch -c tier2/<track-name> origin/master` (NOT `git checkout` - it is banned)
|
|
3. Initialize failcount state at `<app-data>/tier2/<track-name>/state.json` (use `load_state` or fresh state)
|
|
4. For each task in `plan.md`:
|
|
a. Red: delegate test creation to @tier3-worker
|
|
b. Run tests via `uv run python scripts/run_tests_batched.py` (NEVER `uv run pytest` directly; the batched runner provides tier filtering, parallelization, and the summary table — added 2026-06-17)
|
|
c. If pass unexpectedly, call `record_red_failure` and check `should_give_up`
|
|
d. Green: delegate implementation to @tier3-worker
|
|
e. Run tests via `scripts/run_tests_batched.py`; if fail, call `record_green_failure` and check `should_give_up`
|
|
f. On green: `record_commit` and `record_green_success` (resets counters)
|
|
g. Commit per task with `git add <specific files> && git commit -m "..."` and attach git note
|
|
h. Update `plan.md` with commit SHA
|
|
5. After all tasks complete, write the end-of-track report (see step 7) and print success summary.
|
|
6. On give-up: call `write_failure_report` from `scripts.tier2.write_report`, print "TRACK ABORTED, see report at <path>".
|
|
7. **End-of-track report** (added 2026-06-17): on success, write `docs/reports/TRACK_COMPLETION_<track-name>.md` following the precedent set by `TRACK_COMPLETION_tier2_autonomous_sandbox_20260616.md`. Update `conductor/tracks/<track-name>/state.toml` to `status = "completed"`. The user reads this report to decide merge.
|
|
|
|
## Conventions (MUST follow - added 2026-06-17)
|
|
|
|
- **Test runner:** use `uv run python scripts/run_tests_batched.py` (NOT `uv run pytest`)
|
|
- **Default branch:** `master` (this repo never had `main`)
|
|
- **Line endings:** preserve existing (CRLF stays CRLF, LF stays LF)
|
|
- **Throw-away scripts:** write to `scripts/tier2/artifacts/<track-name>/`, NOT the base directory
|
|
- **Run-time expectation:** tracks are 1-4 hours. If context runs out, note progress to disk and continue.
|
|
- **Temp files** (added 2026-06-17): NEVER write to `C:\Users\Ed\AppData\Local\Temp\` or `%TEMP%`. Use `C:\Users\Ed\AppData\Local\manual_slop\tier2\` for scratch / audit-output / intermediate files. The bash deny `*AppData\Local\Temp\*` will block writes; the OpenCode session's outer guard will fire the "ask" prompt for reads — both halt autonomous ops.
|
|
|
|
## Hard Bans (enforced by 3 layers)
|
|
|
|
- `git restore*` (any form) — denied
|
|
- `git push*` (any push) — denied
|
|
- `git checkout*` (any form) — denied; use `git switch` instead
|
|
- `git reset*` (any form) — denied
|
|
|
|
Filesystem access is restricted to the Tier 2 clone + `<app-data>/manual_slop/tier2/`. The Windows restricted token blocks reads/writes outside these paths at the OS level.
|